Security

Your resume, protected.

Every technical and operational choice we've made to keep your data safe.

Encryption

  • At rest: AES-256 on our managed database (MongoDB Atlas) and object storage (Cloudflare R2), with per-environment credentials.
  • In transit: TLS 1.3 on every edge; HSTS; no plaintext fallbacks.

Isolation

  • Sign-in and sessions are handled by Clerk; every backend request is verified against your signed session token before any data is read.
  • Per-user data is partitioned by user ID at the query layer — cross-user reads are rejected structurally, not by an afterthought check.
  • No long-lived cloud credentials in code: secrets live in the hosting platform's environment store and rotate on change.

AI model providers

  • Matching and auto-apply are powered by frontier models accessed under no-training API terms — your data is not used to train anyone's models.
  • Your resume and profile details are sent to a model provider only to power features you invoke — scoring your fit for a job, or filling an application you approved. They are never sold, shared for advertising, or used for anything else.
  • Analytics and telemetry are PII-stripped before they leave the request path — names, emails, and resume text never enter our analytics tooling.

Compliance

  • SOC 2 Type I — engaged, targeting 2026 Q3.
  • GDPR — data subject access, portability, and deletion implemented.
  • CCPA / CPRA — request portal at /legal/ccpa/.
  • DPA for B2B at /legal/dpa/.

Responsible disclosure

We run a private disclosure program. Email security@jobeezy.com with details (PGP-encrypted preferred). We acknowledge within 24 hours and fix critical issues within 7 days. Public disclosure welcome after a fix ships.

Incident history

No security incidents disclosed. We will update this page within 72 hours of detection of any qualifying event.